A public access-control flaw allows unauthenticated users to retrieve the full user list from GET /api/allusers. This exposes user profile metadata to anyone who can reach the application and enables remote user enumeration.
The vulnerable route is registered as a public endpoint:
internal/router/user.go:17
appRouterGroup.PublicRouterGroup.GET("/allusers", h.UserHandler.GetAllUsers())However, the handler appears to have been intended as an authenticated endpoint:
internal/handler/user/user.go:177-185
@Security ApiKeyAuthThis creates a mismatch between the documented security model and the actual routing configuration. As a result, requests to GET /api/allusers succeed without authentication and return user records, including profile metadata such as usernames, email addresses, role-related flags, avatar values, and locale information.
A negative control against another endpoint that correctly requires authentication further supports that this exposure is unintended: GET /api/user returns 401 Unauthorized when no token is supplied, while GET /api/allusers remains publicly accessible.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-24T22:25:03Z",
"nvd_published_at": "2026-03-26T21:17:07Z",
"severity": "MODERATE"
}